43% Breached and Nobody Is Surprised: What the DSIT Survey Really Tells Us About UK Business Security Mauven MacLeod · 20 May 2026
43% of UK businesses breached. Revenue impact doubled. Board engagement finally rising. Mauven MacLeod reads between the lines of the DSIT survey.
Read more → Microsoft Calls It Information Disclosure. The Rest of Us Call It MFA Bypass. Noel Bradford · 20 May 2026
Microsoft calls CVE-2026-41615 information disclosure. It is an MFA bypass. The Authenticator app leaks work account tokens after one user tap.
Read more → What The NCSC Has Been Telling You About BitLocker For Years Mauven MacLeod · 20 May 2026
The NCSC's Windows guidance has recommended TPM plus PIN for years. Most UK organisations ignored it. YellowKey just changed what that decision costs.
Read more → Concern Is Not a Control: Why UK Small Business Cyber Hygiene Went Backwards While Awareness Went Up Mauven MacLeod · 6 May 2026
Awareness went up. Risk assessments went down. Continuity plans dropped 9 points. If concern was a control, the survey numbers would look very different.
Read more → A Black Box with Flashy Lights: The NCSC's SilentGlass and the Question Nobody Is Asking Mauven MacLeod · 28 April 2026
NCSC's SilentGlass is technically sound government kit, now available commercially. But if you're still fighting phishing, it's probably not your next purchase.
Read more → How AI Is Changing State-Sponsored Cyber Threats for UK SMBs Kathryn Renaud · 26 April 2026
State-sponsored attackers are reaching small businesses through the systems they already rely on. Here is how to spot it and respond.
Read more → April 2026 Patch Tuesday: 167 CVEs, Two Zero-Days, and a Deadline You Cannot Afford to Miss Graham Falkner · 15 April 2026
167 CVEs. Two zero-days. One SharePoint flaw needs no password to exploit. April 2026 Patch Tuesday demands your attention today, not next week.
Read more → Red Canary's March 2026 Threat Report: What UK Small Businesses Need to Do This Week Graham Falkner · 8 April 2026
Paste-and-run is now the dominant attack method. Mac is not safe. Vidar is back. Red Canary's March data, translated into steps you can actually take.
Read more → Unsupported Software and UK GDPR: The Compliance Risk You Cannot Ignore Mauven MacLeod · 1 April 2026
Article 32 of UK GDPR requires 'appropriate technical measures' to protect personal data. Running unpatched, out-of-support software is very difficult to defend as appropriate.
Read more →